znc kayıtları
znc üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %82,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-476 NULL Pointer Dereference2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-399 Resource Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2024-39844Kavram kanıtı | In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.CWE-94 | Kritik9,8 | — | %3,9 | 3 Tem 2024 |
40Planlayın | CVE-2020-29577İstismar yok | The official znc docker images before 1.7.1-slim contain a blank password for a root user.znc · znc docker image | Kritik9,8 | — | %2,3 | 8 Ara 2020 |
36İzleyin | CVE-2019-12816İstismar yok | Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loadingznc · znc · CWE-20 | Yüksek8,8 | — | %4,1 | 15 Haz 2019 |
31İzleyin | CVE-2009-2658İstismar yok | Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.znc · znc · CWE-22 | Yüksek7,5 | — | %2,9 | 4 Ağu 2009 |
31İzleyin | CVE-2010-2488İstismar yok | NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections.znc · znc · CWE-476 | Yüksek7,5 | — | %2,4 | 12 Kas 2019 |
27İzleyin | CVE-2019-9917İstismar yok | ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.znc · znc · CWE-20 | Orta6,5 | — | %3,1 | 27 Mar 2019 |
27İzleyin | CVE-2009-0759İstismar yok | Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuratioznc · znc · CWE-94 | Orta6,5 | — | %2,1 | 3 Mar 2009 |
27İzleyin | CVE-2020-13775İstismar yok | ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is noznc · znc · CWE-476 | Orta6,5 | — | %1,8 | 2 Haz 2020 |
26İzleyin | CVE-2018-14055İstismar yok | ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilegeznc · znc · CWE-20 | Orta6,5 | — | %1,5 | 14 Tem 2018 |
22İzleyin | CVE-2018-14056İstismar yok | ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.znc · znc · CWE-22 | Orta5,3 | — | %2,0 | 14 Tem 2018 |
21İzleyin | CVE-2010-2812İstismar yok | Client.cpp in ZNC 0.092 allows remote attackers to cause a denial of service (exception and daemon crash) via a PING command that lacks an aznc · znc · CWE-20 | Orta5,0 | — | %3,2 | 17 Ağu 2010 |
21İzleyin | CVE-2010-2934İstismar yok | Multiple unspecified vulnerabilities in ZNC 0.092 allow remote attackers to cause a denial of service (exception and daemon crash) via unknoznc · znc | Orta5,0 | — | %3,1 | 17 Ağu 2010 |
21İzleyin | CVE-2012-0033İstismar yok | The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc module in ZNC 0.200 and 0.202 allows remote attackers to cause a deznc · znc-msvc · CWE-399 | Orta5,0 | — | %2,4 | 8 Nis 2014 |
17İzleyin | CVE-2013-2130İstismar yok | ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted request to the (1) eznc · znc | Orta4,0 | — | %2,2 | 5 Haz 2014 |
17İzleyin | CVE-2014-9403İstismar yok | The CWebAdminMod::ChanPage function in modules/webadmin.cpp in ZNC before 1.4 allows remote authenticated users to cause a denial of serviceznc · znc | Orta4,0 | — | %2,2 | 19 Ara 2014 |
17İzleyin | CVE-2013-7049İstismar yok | Stack-based buffer overflow in fish.cpp in the Fish plugin for ZNC, as used in ZNC for Windows (znc-msvc) 0.206 and earlier, allows remote aznc · znc-msvc · CWE-119 | Orta4,3 | — | %1,7 | 23 Ara 2013 |
15İzleyin | CVE-2010-2448İstismar yok | znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when theznc · znc | Düşük3,5 | — | %2,1 | 12 Tem 2010 |
- CVE-2024-3984440Planlayın
In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
KritikCVSS 9,8Kavram kanıtıEPSS %43 Tem 2024
- CVE-2020-2957740Planlayın
The official znc docker images before 1.7.1-slim contain a blank password for a root user.
KritikCVSS 9,8İstismar yokEPSS %2znc · znc docker image8 Ara 2020
- CVE-2019-1281636İzleyin
Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading
YüksekCVSS 8,8İstismar yokEPSS %4znc · znc15 Haz 2019
- CVE-2009-265831İzleyin
Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.
YüksekCVSS 7,5İstismar yokEPSS %3znc · znc4 Ağu 2009
- CVE-2010-248831İzleyin
NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections.
YüksekCVSS 7,5İstismar yokEPSS %2znc · znc12 Kas 2019
- CVE-2019-991727İzleyin
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
OrtaCVSS 6,5İstismar yokEPSS %3znc · znc27 Mar 2019
- CVE-2009-075927İzleyin
Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuratio
OrtaCVSS 6,5İstismar yokEPSS %2znc · znc3 Mar 2009
- CVE-2020-1377527İzleyin
ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is no
OrtaCVSS 6,5İstismar yokEPSS %2znc · znc2 Haz 2020
- CVE-2018-1405526İzleyin
ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege
OrtaCVSS 6,5İstismar yokEPSS %1znc · znc14 Tem 2018
- CVE-2018-1405622İzleyin
ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.
OrtaCVSS 5,3İstismar yokEPSS %2znc · znc14 Tem 2018
- CVE-2010-281221İzleyin
Client.cpp in ZNC 0.092 allows remote attackers to cause a denial of service (exception and daemon crash) via a PING command that lacks an a
OrtaCVSS 5,0İstismar yokEPSS %3znc · znc17 Ağu 2010
- CVE-2010-293421İzleyin
Multiple unspecified vulnerabilities in ZNC 0.092 allow remote attackers to cause a denial of service (exception and daemon crash) via unkno
OrtaCVSS 5,0İstismar yokEPSS %3znc · znc17 Ağu 2010
- CVE-2012-003321İzleyin
The CBounceDCCMod::OnPrivCTCP function in bouncedcc.cpp in the bouncedcc module in ZNC 0.200 and 0.202 allows remote attackers to cause a de
OrtaCVSS 5,0İstismar yokEPSS %2znc · znc-msvc8 Nis 2014
- CVE-2013-213017İzleyin
ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted request to the (1) e
OrtaCVSS 4,0İstismar yokEPSS %2znc · znc5 Haz 2014
- CVE-2014-940317İzleyin
The CWebAdminMod::ChanPage function in modules/webadmin.cpp in ZNC before 1.4 allows remote authenticated users to cause a denial of service
OrtaCVSS 4,0İstismar yokEPSS %2znc · znc19 Ara 2014
- CVE-2013-704917İzleyin
Stack-based buffer overflow in fish.cpp in the Fish plugin for ZNC, as used in ZNC for Windows (znc-msvc) 0.206 and earlier, allows remote a
OrtaCVSS 4,3İstismar yokEPSS %2znc · znc-msvc23 Ara 2013
- CVE-2010-244815İzleyin
znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when the
DüşükCVSS 3,5İstismar yokEPSS %2znc · znc12 Tem 2010